← SwiftSwap Home

Security & Responsible Disclosure

We take security seriously. If you've found a vulnerability, here's how to report it responsibly.

Found a security issue? Please email security@swiftswap.net before any public disclosure. We respond within 48 hours and pay rewards for verified vulnerabilities.

Our Security Commitment

SwiftSwap is built on a non-custodial architecture — user funds go wallet-to-wallet and are never held by our platform. This significantly reduces our attack surface. However, we continuously work to identify and fix vulnerabilities in our web application, API, and infrastructure.

Responsible Disclosure Policy

Please DO:

Please DO NOT:

Bug Bounty Rewards

Severity Description Reward
Critical Fund theft, authentication bypass, complete system compromise Up to $5,000 USDT
High Privilege escalation, significant data breach potential, payment fraud Up to $1,000 USDT
Medium Information disclosure, XSS with significant impact, rate limit bypass Up to $200 USDT
Low Minor information disclosure, low-impact vulnerabilities Up to $50 USDT

In-Scope Assets

Out-of-Scope

Disclosure Timeline

We commit to the following response times:

How to Submit a Report

Send your report to security@swiftswap.net

Please include:

For sensitive reports, you may encrypt your email using our PGP key (available on request).

Security Contact

Email: security@swiftswap.net

Response time: Within 48 hours

Program status: Active

SwiftSwap participates in coordinated vulnerability disclosure. We will not take legal action against researchers who follow this policy.